Back to articles
Technology Insight

Deploying Logto Auth Server on Cloud VPS: Next-Gen Identity Management (OIDC/OAuth2) for Modern Web and Mobile Apps

June 2, 2026

Introduction to Modern Identity Management

In the rapidly evolving landscape of web and mobile application development, implementing a robust, secure, and scalable authentication and authorization system is no longer optional. Traditional, siloed user management systems—where credentials are stored in monolithic databases and managed via custom-coded session logic—are increasingly vulnerable to security breaches and fail to meet the demands of modern multi-platform ecosystems. Today, businesses require centralized, standards-compliant identity solutions that support single sign-on (SSO), multi-factor authentication (MFA), and seamless third-party integrations.

While commercial Identity-as-a-Service (IDaaS) providers offer convenience, they often come with escalating costs that scale predictably with monthly active users (MAUs), along with rigid vendor lock-in and data residency concerns. This is where Logto emerges as a game-changing alternative. Logto is a powerful, open-source identity verification and access control solution built on top of OpenID Connect (OIDC) and OAuth2 frameworks. By deploying Logto on an independent Cloud Virtual Private Server (VPS), organizations can retain absolute sovereignty over their user data, customize the authentication experience entirely, and eliminate unpredictable recurring licensing fees. This comprehensive guide explores why and how to deploy Logto as your self-hosted centralized Auth Server.

The Core Architecture: Why Logto, OIDC, and OAuth2?

Modern application architectures rely heavily on decoupled front-ends (Single Page Applications like React, Vue, or Angular) and decentralized microservices or API Gateways. Securing this topology requires an identity layer that speaks a standardized language. Logto implements two of the most critical web standards to achieve this:

  • OAuth 2.0: The industry-standard protocol for authorization, allowing applications to obtain limited access to user accounts on an HTTP service via access tokens.
  • OpenID Connect (OIDC): An identity layer built on top of the OAuth 2.0 protocol, allowing clients to verify the identity of the end-user based on the authentication performed by an Authorization Server, obtaining basic profile information via ID tokens.

By coupling these protocols with a modern, developer-centric interface, Logto minimizes the friction traditionally associated with setting up identity infrastructure. It provides out-of-the-box support for popular social sign-ins (Google, GitHub, Apple), passwordless authentication (SMS/Email OTP), and enterprise SSO (SAML, OIDC) through an intuitive Admin Console. Choosing a self-hosted Cloud VPS for this deployment balances administrative control with infrastructure agility, allowing IT departments to scale compute resources, implement custom firewall rules, and maintain compliance with strict local data protection regulations.

Prerequisites and Cloud VPS Provisioning

Before initiating the deployment process, ensure your infrastructure meets the minimum baseline requirements to guarantee high availability and responsive token issuance. Logto is written in TypeScript and backed by PostgreSQL, meaning it is highly efficient but requires sufficient memory for connection pooling and cryptographic operations.

Hardware & OS Recommendations

  • CPU: Minimum 2 vCPUs (Optimized for compute if high authentication traffic is expected).
  • RAM: Minimum 2GB RAM (4GB recommended for production environments containing high-concurrency background jobs).
  • Storage: 20GB+ SSD/NVMe storage.
  • Operating System: Ubuntu 22.04 LTS or Ubuntu 24.04 LTS for maximum package compatibility.

Networking Requirements

An authorized authentication server must communicate over secure channels. You will need a registered Fully Qualified Domain Name (FQDN) (e.g., auth.yourcompany.com) pointing via an A Record to your Cloud VPS static IPv4 address. Additionally, verify that ports 80 (HTTP), 443 (HTTPS), and 3002/3001 (Logto internal administration/core default ports, if exposed directly) are properly configured on your cloud firewall provider.

Step-by-Step Guide to Deploying Logto via Docker Compose

Utilizing containerization is the recommended mechanism for deploying Logto. It isolates runtime dependencies, simplifies engine upgrades, and ensures environmental consistency. Follow these structured steps to initialize your Logto environment.

Step 1: Install Docker and Docker Compose

Connect to your Cloud VPS via SSH and execute the following commands to update the system and install the official Docker Engine container runtime ecosystem:

sudo apt update && sudo apt upgrade -y
sudo apt install -y curl git secure-delete
curl -fsSL [https://get.docker.com](https://get.docker.com) -o get-docker.sh
sudo sh get-docker.sh

Verify your installation is active and running properly using sudo docker info.

Step 2: Configure the Docker Compose Environment

Create a dedicated directory for your identity management infrastructure and initialize a docker-compose.yml file. This configuration initializes both a Logto instance and an isolated PostgreSQL database container.

version: '3.8'

services:
postgres:
image: postgres:14-alpine
container_name: logto-postgres
environment:
POSTGRES_USER: logto_admin
POSTGRES_PASSWORD: StrongSecurePassword123!
POSTGRES_DB: logto_identity
volumes:
- pgdata:/var/lib/postgresql/data
networks:
- logto-network
restart: always

logto:
image: svhd/logto:latest
container_name: logto-core
ports:
- "3001:3001"
- "3002:3002"
environment:
- DB_URL=postgresql://logto_admin:StrongSecurePassword123!@postgres:5432/logto_identity
- ENDPOINT=[https://auth.yourcompany.com](https://auth.yourcompany.com)
- ADMIN_ENDPOINT=[https://admin-auth.yourcompany.com](https://admin-auth.yourcompany.com)
depends_on:
- postgres
networks:
- logto-network
restart: always

volumes:
pgdata:

networks:
logto-network:
driver: bridge

Note: Replace StrongSecurePassword123! with a cryptographically secure string, and update the endpoints to mirror your designated production domains.

Step 3: Database Initialization and Container Start

Logto requires a database migration sequence to seed schema structures, tables, and indices before running the web app core server. Run the following command to execute the migration utility script inside the container container environment:

docker compose run logto npm run alteration deploy latest

Once the database scheme migration successfully returns a termination code of zero, initiate your application services in detached background mode:

docker compose up -d

Securing Your Logto Server with an Nginx Reverse Proxy

Exposing database ports or raw application runtimes directly to the public internet violates basic infrastructure hardening protocols. Implementing an Nginx Reverse Proxy establishes a single point of entry, terminates TLS/SSL certificates, masks underlying service headers, and mitigates DDoS risks.

1. Install Nginx

Install the Nginx HTTP server native binary using your system package management system: sudo apt install nginx -y.

2. Configure Virtual Host Blocks

Create an Nginx configuration file under /etc/nginx/sites-available/logto.conf to manage routing rules for both the frontend authentication endpoints and the administrative back-office UI wrapper:

server {
listen 80;
server_name auth.yourcompany.com;
location / {
proxy_pass http://localhost:3001;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}

server {
listen 80;
server_name admin-auth.yourcompany.com;
location / {
proxy_pass http://localhost:3002;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}

Enable the site configuration by establishing a symlink to the active site directory and reload Nginx: sudo ln -s /etc/nginx/sites-available/logto.conf /etc/nginx/sites-enabled/ && sudo systemctl reload nginx.

3. Provision Automated SSL Certs via Let's Encrypt

Secure all data in transit using industry-standard TLS encryption. Install Certbot and its associated Nginx hook plugin to automatically fetch and configure zero-cost SSL certificates:

sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d auth.yourcompany.com -d admin-auth.yourcompany.com

Follow the interactive prompts to enable automatic HTTPS redirection, ensuring all plain text requests are permanently upgraded to secure TLS paths.

Integrating Your First Application

With Logto successfully running and secured behind your domain, navigating to [https://admin-auth.yourcompany.com](https://admin-auth.yourcompany.com) presents the out-of-the-box administrator initialization wizard. Here you will configure the master administrative credentials.

To connect an external application (e.g., a Next.js web portal or a Flutter mobile app) to your identity stack:

  1. Navigate to the Applications tab inside the Logto Console UI.
  2. Click Create Application and select the appropriate integration framework template corresponding to your technology stack.
  3. Note the auto-generated Application ID (Client ID) and Application Secret values.
  4. Configure the mandatory Redirect URIs (the callback path within your app processing token responses, such as http://localhost:3000/callback) and Post Sign-out Redirect URIs to protect against open-redirect vulnerabilities.

Incorporate the official Logto SDK library into your source code codebase, feeding it your server's endpoint domain and credentials to immediately secure application routes with fewer lines of manual code boilerplate.

Conclusion and Best Practices

Deploying Logto on an isolated Cloud VPS delivers enterprise-grade, OIDC/OAuth2 compliant identity architecture completely under your operational domain. To maintain an optimized posture long-term, ensure you execute standard maintenance routines:

  • Automated Database Backups: Schedule a cron job executing pg_dump hourly or daily, offloading encrypted snapshots to secure object storage repositories.
  • Resource Monitoring: Track memory footprints and query performance spikes during shifts in user login velocity.
  • Keep Software Updated: Regularly pull updated container tags from Logto's distribution registry to maintain patch compatibility against critical CVE security vulnerabilities.

By migrating your authentication workloads to a self-managed server instance, you protect customer privacy, future-proof API infrastructure boundaries, and position your digital product for limitless architectural scale.

Deploying Logto Auth Server on Cloud VPS: Next-Gen Identity Management (OIDC/OAuth2) for Modern Web and Mobile Apps | DPTCloud